Vincenzo Udinesi
Junior Member
- Jan 14, 2019
- 186
- 63
Hi all the great people out there,
2 out of my 5 websites on a single Bluehost account have been hacked yesterday and I am not able to figure out how to stop this from happening again.
The hacked websites are the only sites with some traffic so I doubt that the hacker did not touch other sites intentionally as it was of no value to him.
Yesterday I received an email from Google Search Console Team saying "Social engineering content detected on https://www.mysite1.com"
I visited website(with a vpn) to see what was going on and there was a Chinese(or some other Asian) language website being loaded instead of my homepage, I visited other post pages and they were all fine.
Today, I received another email from Google Search Console Team saying "Google has identified that [email protected](original email) has been added as an owner of https://mysite2.com" I am the only owner and when I logged into Search Console, I could not see any other owner(may be the hacker deleted himself).
I contacted Bluehost and they scanned my account for malware, later they emailed me a malware.txt file which contains a list of 23 infected files: 21 files are php and 2 are .htaccess.
Hosting company suspended my account temporarily.
Now, how should I go about it?
Deleting those 2 Wordpress installations inside hosting account and reinstalling from backups would be enough?
Please guide me about what measures to take, thank you for in advance
2 out of my 5 websites on a single Bluehost account have been hacked yesterday and I am not able to figure out how to stop this from happening again.
The hacked websites are the only sites with some traffic so I doubt that the hacker did not touch other sites intentionally as it was of no value to him.
Yesterday I received an email from Google Search Console Team saying "Social engineering content detected on https://www.mysite1.com"
I visited website(with a vpn) to see what was going on and there was a Chinese(or some other Asian) language website being loaded instead of my homepage, I visited other post pages and they were all fine.
Today, I received another email from Google Search Console Team saying "Google has identified that [email protected](original email) has been added as an owner of https://mysite2.com" I am the only owner and when I logged into Search Console, I could not see any other owner(may be the hacker deleted himself).
I contacted Bluehost and they scanned my account for malware, later they emailed me a malware.txt file which contains a list of 23 infected files: 21 files are php and 2 are .htaccess.
Hosting company suspended my account temporarily.
Now, how should I go about it?
Deleting those 2 Wordpress installations inside hosting account and reinstalling from backups would be enough?
- Both websites have very popular themes and some 5-6 plugins like Yoast etc.
- Wordpress versions were regularly updated.
- No nulled themes, plugins were used.
Please guide me about what measures to take, thank you for in advance